Security
Vulnerability disclosure policy
If you believe you have discovered a security vulnerability in Memo, please report it promptly to our security team. Do not include sensitive information, customer data, or live credentials in initial reports - provide enough detail for us to reproduce the issue safely. We do not currently operate a paid bounty program, and we do not promise specific response timelines, compensation, or legal safe harbor beyond what is stated in our Vulnerability Disclosure Policy.
1. Purpose
Memo welcomes good-faith security research that helps us protect users. This policy describes how to report vulnerabilities, what is in scope, and what you can expect from us. This policy does not modify the Terms of Service or create contractual obligations beyond what is stated here.
2. Reporting
Report suspected vulnerabilities to security@memo.ly. Provide a clear description, steps to reproduce, and the potential impact. Do not include customer data, live credentials, or large exploit payloads in your initial report. We may request additional information through a secure channel.
3. In scope
- memo.ly and the Memo authenticated application on app.memo.ly.
- Cross-tenant isolation, authentication, authorization, and unintended data exposure within Memo-controlled systems.
- Server-side vulnerabilities in Memo-controlled APIs and webhooks that you can demonstrate safely without harming other users.
4. Out of scope
- Denial-of-service attacks, load testing, spam, or activity that degrades service availability for other users.
- Social engineering of Memo personnel, partners, or customers.
- Physical security, client-side issues in third-party browsers or extensions, or vulnerabilities in third-party services outside Memo control (report those to the relevant vendor).
- Issues in customer-created email HTML exported to or sent through external platforms.
- Automated scanning or testing that violates the Acceptable Use Policy or applicable law.
- Findings based solely on missing security headers without demonstrated exploitability.
5. Safe harbor
If you conduct research in good faith in accordance with this policy - including making a prompt report, avoiding privacy violations, not accessing data beyond what is necessary to demonstrate the issue, and giving Memo reasonable time to remediate before public disclosure - Memo will not initiate legal action against you solely for such research. This safe harbor does not extend to conduct that violates law, harms Memo or its users, or falls outside scope. Memo does not promise immunity from third-party claims and does not currently operate a paid bug bounty program.
6. Public disclosure
Do not publicly disclose a vulnerability until Memo confirms remediation or agrees in writing to a coordinated disclosure timeline. Premature disclosure may void safe harbor consideration.
7. Response expectations
Memo aims to acknowledge valid reports within a few business days and to provide a substantive update once impact is understood. These are targets, not guarantees. Memo does not currently operate a paid bounty program and does not promise specific remediation timelines or compensation.
8. Governing law
This policy is governed by the laws of the State of Montana, United States, without regard to conflict-of-law principles.
Machine-readable contact: security.txt. See also Security overview, Privacy Policy, and Acceptable Use.